The $33 Billion AI Security Opportunity artwork

The $33 Billion AI Security Opportunity

Thoughts on the Market

September 1, 2026

As AI agents gain access to sensitive enterprise systems, companies need new ways to control what they can do. Meta Marshall breaks down the emerging market for agentic identity security. Read more insights from Morgan Stanley.
Speakers: Meta Marshall

Topics: Investing, Business

**Meta Marshall** (0:00)
Welcome to Thoughts on the Market. I'm Meta Marshall, Morgan Stanley's US. Cybersecurity and Telecom and Network Equipment Analyst. Today, AI assistants are starting to act on our behalf at work, which brings up a critical question. What should these agents be allowed to do, and how should those permissions be granted? It's Tuesday, September 1st, at 10 a.m. in New York.
More and more, AI is helping us get through the workday. We ask it to summarize documents, analyze data, and take notes during meetings.
Increasingly, though, these tools are moving beyond just answering questions to acting on our behalf. Suddenly, the security challenge shifts from managing a tool to governing a whole new digital workforce. In coming years, this problem should get bigger, as we estimate seeing 79 AI agents and 109 machine identities for every human employee. Now, traditional identity security at work was built to answer two basic questions. Who are you and what can you access? Think of it as your office badge. It identifies you and determines what doors you can open. AI agents, however, make that question much harder to answer. They can operate autonomously, move across applications and databases, collaborate with other agents. They take actions without direct human involvement. So companies need to know not only what an agent can access, but why it needs access, for how long, and what it actually did. That's the core foundation of agentic identity solutions. The risk environment from this problem is already substantial. About 80% of breaches in the work environment today involve stolen or misused credentials. Nine out of ten organizations experienced an identity-related breach in the past year, and 83% experienced at least two.
Now add potentially hundreds of machine and AI identities for every human, each operating continuously and at machine speed, and the problem is much larger. One solution to managing AI agents is zero standing privilege. Instead of giving an agent permanent access, you give it permission for a specific task and revoke that permission when the job is done. Here's the issue, though. Today, only 39% of privileged access is managed through this just-in-time or zero standing privilege architecture. And the reality is, is that humans can't approve every request. More of those decisions will need to happen automatically, in real time, through what's known as runtime governance.
We estimate as a result that agentic identity alone could become a roughly $33 billion global opportunity in our base case, which brings the overall identity market opportunity to more than $60 billion in coming years. This need for agentic identity coming from AI could also push historically fragmented industry towards a more unified platform. In one industry survey, 85% of organizations said fragmented identity systems delay their human response to identity threats, with respondents citing an average of 12 hours needed to respond per incident. We think that favors platforms that can manage human and machine identities together and make security decisions dynamically, overall making a more secure environment.
This transition won't happen overnight. Agentic identity products are still early, and we don't expect an immediate financial impact. But as enterprises move from experimenting with AI agents to deploying them more broadly, spending to secure those agents could become a more meaningful growth tailwind in 2027
The longer term growth opportunity comes down to a simple dynamic. More agents, with more autonomy, will require more control. And that could make identity security essential to scaling AI across the enterprise.
Thanks for listening. If you enjoy the show, please leave us a review wherever you listen, and share thoughts on the market with a friend or colleague today.

**SPEAKER_2** (4:00)
The preceding content is informational only and based on information available when created. It is not an offer or solicitation, nor is it tax or legal advice. It does not consider your financial circumstances and objectives and may not be suitable for you.

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID